Close Menu
    What's Hot

    How XRP relates to CBDC infrastructure in 2026

    January 17, 2026

    Ripple’s Business Growth: Navigating Regulatory Challenges in 2026

    January 14, 2026

    XRP Regulatory Clarity: Legal Challenges and Market Impact in 2026

    January 14, 2026
    YouTube Telegram
    • Home
    • Markets
    • VIP
    Facebook X (Twitter) Instagram
    cryptogiant
    • Home
    • NEWS
      • Bitcoin
      • xrp
      • Markets
      • Altcoins
    • Prices
    • Guide
    • Reviews
    • VIP
    cryptogiant
    Home»Markets»Trust Wallet Exploit Drains $7M From Chrome Extension Users
    Markets

    Trust Wallet Exploit Drains $7M From Chrome Extension Users

    Bella ABy Bella ADecember 28, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Trust Wallet Exploit Drains $7M From Chrome Extension Users
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Trust Wallet users lost almost $7 million shortly after the company introduced an updated version of its Chrome plugin. Changpeng Zhao, a co-founder of Binance, the cryptocurrency exchange that owns the utility, said the stolen funds would be returned.

    The wallet team acknowledged the hack, which was first reported on December 25 by on-chain detective ZachXBT.

    Trust Wallet is asking users to update its Google Chrome extension to the most recent version following a “security incident” that resulted in a loss of nearly $7 million.

    The non-custodial cryptocurrency wallet service reported an issue with version 2.68. The extension has approximately one million users, according to the Chrome Web Store listing. Users should update to version 2.69 as soon as possible.

    “We’ve confirmed that approximately $7M has been impacted, and we will ensure that all affected users are refunded,” Trust Wallet stated in a post on X. “Supporting affected users is our top priority, and we are actively finalising the process to refund the impacted users.”

    We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.

    Please refer to the official Chrome Webstore link here: https://t.co/V3vMq31TKb

    Please note: Mobile-only users…

    — Trust Wallet (@TrustWallet) December 25, 2025

    Trust Wallet further advises customers to avoid interacting with any messages that do not originate from its official channels. Mobile-only users and all other browser extension versions are unaffected.

    Trust Wallet stated that the vulnerability was limited to the Chrome browser extension and did not affect its mobile apps or the underlying blockchains themselves. A corrected version, 2.69, was issued soon after the problem was discovered.

    According to SlowMist, version 2.68 included malicious code that was designed to run through all wallets stored in the extension and request a mnemonic phrase for each one.

    “The encrypted mnemonic is then decrypted using the password or passkeyPassword entered during wallet unlock,” the blockchain security company stated. “Once decrypted, the mnemonic phrase is sent to the attacker’s server api.metrics-trustwallet[.]com.”

    The domain “metrics-trustwallet[.]com” was registered on December 8, 2025, and the first request to “api.metrics-trustwallet[.]com” took place on December 21, 2025.

    The attacker used posthog-js, an open-source full-chain analytics tool, to gather wallet user information.

    The digital assets drained thus far include approximately $3 million in Bitcoin, $431 in Solana, and more than $3 million in Ethereum. The stolen cash was transferred through centralised exchanges and cross-chain bridges for laundering and swapping. According to a report released by blockchain investigator ZachXBT, hundreds of people fell victim to the incident.

    “While ~$2.8 million of the stolen funds remain in the hacker’s wallets (Bitcoin/ EVM/ Solana), the bulk – >$4M in cryptos – has been sent to CEXs [centralised exchanges]: ~$3.3 million to ChangeNOW, ~$340,000 to FixedFloat, and ~$447,000 to KuCoin,” disclosed PeckShield.

    “This backdoor incident originated from malicious source code modification within the internal Trust Wallet extension codebase (analytics logic), rather than an injected compromised third‑party dependency (e.g., malicious npm package),” according to SlowMist.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Bella A

    Related Posts

    Crypto Derivatives Surge to $86T as Institutions Take Over

    December 26, 2025

    Polymarket Security Breach Linked to Magic Labs Login

    December 25, 2025

    Ethereum ETFs See $600M Outflows, Signaling Bearish Shift

    December 23, 2025

    Coinbase Unveils Stocks, Futures, and Prediction Markets

    December 20, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    How XRP relates to CBDC infrastructure in 2026

    January 17, 2026

    Ripple’s Business Growth: Navigating Regulatory Challenges in 2026

    January 14, 2026

    XRP Regulatory Clarity: Legal Challenges and Market Impact in 2026

    January 14, 2026

    XRP Addressing Regulatory Clarity and Legal Challenges

    January 12, 2026

    Trust Wallet Exploit Drains $7M From Chrome Extension Users

    December 28, 2025

    Subscribe to Updates

    Get the latest news from CryptoGaint about Crypto, stock and Finance.

    Crypto Giant

    Your source for the serious crypto news and insights.

    We're social. Connect with us:

    YouTube Telegram
    Top Insights

    How XRP relates to CBDC infrastructure in 2026

    January 17, 2026

    Ripple’s Business Growth: Navigating Regulatory Challenges in 2026

    January 14, 2026

    XRP Regulatory Clarity: Legal Challenges and Market Impact in 2026

    January 14, 2026

    XRP Addressing Regulatory Clarity and Legal Challenges

    January 12, 2026

    Trust Wallet Exploit Drains $7M From Chrome Extension Users

    December 28, 2025
    Get Informed

    Subscribe to Updates

    Get the latest creative news from cryptogiant about crypto, finance and investing.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Altcoins
    • VIP
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.